Rewterz Threat Alert – Orcus RAT – Active IOCs
August 17, 2021Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs
August 17, 2021Rewterz Threat Alert – Orcus RAT – Active IOCs
August 17, 2021Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs
August 17, 2021Severity
High
Analysis Summary
Gootkit is complex multi-stage banking malware has been arround since 2014. Initially it was distributed via spam and exploits kits such as Spelevo and RIG. In conjunction with spam campaigns, the adversaries later switched to compromised websites where the visitors are tricked into downloading the malware. Gootkit is capable of stealing data from the browser, performing man-in-the-browser attacks, keylogging, taking screenshots and lots of other malicious actions. Its loader performs various virtual machine and sandbox checks and uses sophisticated persistence algorithms. In 2019, Gootkit stopped operating after it experienced a data leak, but has been active again since November 2020. Gootkit’s victims are mainly located in EU countries such as Germany and Italy.
Impact
- Unauthorized Access
Indicators of Compromise
MD5
- 1f92c45c4c98819da94648146eb940d8
SHA-256
- 14833d90e142456ccaf88e200ae5ecede234bbf5424f0b6ad7ccad2eb7865c64
SHA-1
- c9a4093fd7362fdb462f523dc21fb8ec654bfba3
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.
- Do not download files from untrusted sources or emails.